CVE-2018-12208

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:server_platform_services_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:44

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20190318-0001/ - () https://security.netapp.com/advisory/ntap-20190318-0001/ -
References () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03914en_us - () https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03914en_us -
References () https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html - Vendor Advisory () https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html - Vendor Advisory

Information

Published : 2019-03-14 20:29

Updated : 2024-11-21 03:44


NVD link : CVE-2018-12208

Mitre link : CVE-2018-12208

CVE.ORG link : CVE-2018-12208


JSON object : View

Products Affected

intel

  • server_platform_services_firmware
  • converged_security_management_engine_firmware
  • trusted_execution_engine_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer